CreateProcessInternalW
|
thread_identifier:
2220
thread_handle:
0x000001b8
process_identifier:
2216
current_directory:
filepath:
track:
1
command_line:
C:\Users\test22\AppData\Local\Temp\wlanext.exe /stext "C:\Users\test22\AppData\Local\Temp\isvacpgykhaypum"
filepath_r:
stack_pivoted:
0
creation_flags:
4
(CREATE_SUSPENDED)
inherit_handles:
0
process_handle:
0x00000330
|
1
|
1 |
0
|
NtGetContextThread
|
thread_handle:
0x000001b8
|
1
|
0 |
0
|
NtUnmapViewOfSection
|
base_address:
0x00400000
region_size:
4096
process_identifier:
2216
process_handle:
0x00000330
|
1
|
0 |
0
|
NtMapViewOfSection
|
section_handle:
0x00000348
process_identifier:
2216
commit_size:
0
win32_protect:
64
(PAGE_EXECUTE_READWRITE)
buffer:
base_address:
0x00400000
allocation_type:
0
()
section_offset:
0
view_size:
491520
process_handle:
0x00000330
|
1
|
0 |
0
|
NtSetContextThread
|
registers.eip:
2005598660
registers.esp:
1638384
registers.edi:
0
registers.eax:
4678260
registers.ebp:
0
registers.edx:
0
registers.ebx:
2130567168
registers.esi:
0
registers.ecx:
0
thread_handle:
0x000001b8
process_identifier:
2216
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x000001b8
suspend_count:
1
process_identifier:
2216
|
1
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
2284
thread_handle:
0x000001b8
process_identifier:
2280
current_directory:
filepath:
track:
1
command_line:
C:\Users\test22\AppData\Local\Temp\wlanext.exe /stext "C:\Users\test22\AppData\Local\Temp\snbsdhrrypsdzbidpd"
filepath_r:
stack_pivoted:
0
creation_flags:
4
(CREATE_SUSPENDED)
inherit_handles:
0
process_handle:
0x00000330
|
1
|
1 |
0
|
NtGetContextThread
|
thread_handle:
0x000001b8
|
1
|
0 |
0
|
NtUnmapViewOfSection
|
base_address:
0x00400000
region_size:
4096
process_identifier:
2280
process_handle:
0x00000330
|
1
|
0 |
0
|
NtMapViewOfSection
|
section_handle:
0x0000034c
process_identifier:
2280
commit_size:
0
win32_protect:
64
(PAGE_EXECUTE_READWRITE)
buffer:
base_address:
0x00400000
allocation_type:
0
()
section_offset:
0
view_size:
356352
process_handle:
0x00000330
|
1
|
0 |
0
|
NtSetContextThread
|
registers.eip:
2005598660
registers.esp:
1638384
registers.edi:
0
registers.eax:
4543032
registers.ebp:
0
registers.edx:
0
registers.ebx:
2130567168
registers.esi:
0
registers.ecx:
0
thread_handle:
0x000001b8
process_identifier:
2280
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x000001b8
suspend_count:
1
process_identifier:
2280
|
1
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
2348
thread_handle:
0x000001b8
process_identifier:
2344
current_directory:
filepath:
track:
1
command_line:
C:\Users\test22\AppData\Local\Temp\wlanext.exe /stext "C:\Users\test22\AppData\Local\Temp\vpgdeabtmxkqbhxhynhhnq"
filepath_r:
stack_pivoted:
0
creation_flags:
4
(CREATE_SUSPENDED)
inherit_handles:
0
process_handle:
0x00000330
|
1
|
1 |
0
|
NtGetContextThread
|
thread_handle:
0x000001b8
|
1
|
0 |
0
|
NtUnmapViewOfSection
|
base_address:
0x00400000
region_size:
4096
process_identifier:
2344
process_handle:
0x00000330
|
1
|
0 |
0
|
NtMapViewOfSection
|
section_handle:
0x00000350
process_identifier:
2344
commit_size:
0
win32_protect:
64
(PAGE_EXECUTE_READWRITE)
buffer:
base_address:
0x00400000
allocation_type:
0
()
section_offset:
0
view_size:
147456
process_handle:
0x00000330
|
1
|
0 |
0
|
NtSetContextThread
|
registers.eip:
2005598660
registers.esp:
1638384
registers.edi:
0
registers.eax:
4334086
registers.ebp:
0
registers.edx:
0
registers.ebx:
2130567168
registers.esi:
0
registers.ecx:
0
thread_handle:
0x000001b8
process_identifier:
2344
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x000001b8
suspend_count:
1
process_identifier:
2344
|
1
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
2508
thread_handle:
0x00000344
process_identifier:
2504
current_directory:
filepath:
track:
1
command_line:
C:\Users\test22\AppData\Local\Temp\wlanext.exe /stext "C:\Users\test22\AppData\Local\Temp\pwcuagoezt"
filepath_r:
stack_pivoted:
0
creation_flags:
4
(CREATE_SUSPENDED)
inherit_handles:
0
process_handle:
0x00000354
|
1
|
1 |
0
|
NtGetContextThread
|
thread_handle:
0x00000344
|
1
|
0 |
0
|
NtUnmapViewOfSection
|
base_address:
0x00400000
region_size:
4096
process_identifier:
2504
process_handle:
0x00000354
|
1
|
0 |
0
|
NtMapViewOfSection
|
section_handle:
0x0000035c
process_identifier:
2504
commit_size:
0
win32_protect:
64
(PAGE_EXECUTE_READWRITE)
buffer:
base_address:
0x00400000
allocation_type:
0
()
section_offset:
0
view_size:
491520
process_handle:
0x00000354
|
1
|
0 |
0
|
NtSetContextThread
|
registers.eip:
2005598660
registers.esp:
1638384
registers.edi:
0
registers.eax:
4678260
registers.ebp:
0
registers.edx:
0
registers.ebx:
2130567168
registers.esi:
0
registers.ecx:
0
thread_handle:
0x00000344
process_identifier:
2504
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000344
suspend_count:
1
process_identifier:
2504
|
1
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
2568
thread_handle:
0x00000344
process_identifier:
2564
current_directory:
filepath:
track:
1
command_line:
C:\Users\test22\AppData\Local\Temp\wlanext.exe /stext "C:\Users\test22\AppData\Local\Temp\ayhnbzyyvchoxw"
filepath_r:
stack_pivoted:
0
creation_flags:
4
(CREATE_SUSPENDED)
inherit_handles:
0
process_handle:
0x00000354
|
1
|
1 |
0
|
NtGetContextThread
|
thread_handle:
0x00000344
|
1
|
0 |
0
|
NtUnmapViewOfSection
|
base_address:
0x00400000
region_size:
4096
process_identifier:
2564
process_handle:
0x00000354
|
1
|
0 |
0
|
NtMapViewOfSection
|
section_handle:
0x00000360
process_identifier:
2564
commit_size:
0
win32_protect:
64
(PAGE_EXECUTE_READWRITE)
buffer:
base_address:
0x00400000
allocation_type:
0
()
section_offset:
0
view_size:
356352
process_handle:
0x00000354
|
1
|
0 |
0
|
NtSetContextThread
|
registers.eip:
2005598660
registers.esp:
1638384
registers.edi:
0
registers.eax:
4543032
registers.ebp:
0
registers.edx:
0
registers.ebx:
2130567168
registers.esi:
0
registers.ecx:
0
thread_handle:
0x00000344
process_identifier:
2564
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000344
suspend_count:
1
process_identifier:
2564
|
1
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
2636
thread_handle:
0x00000344
process_identifier:
2632
current_directory:
filepath:
track:
1
command_line:
C:\Users\test22\AppData\Local\Temp\wlanext.exe /stext "C:\Users\test22\AppData\Local\Temp\ksmfcrjajkztaclda"
filepath_r:
stack_pivoted:
0
creation_flags:
4
(CREATE_SUSPENDED)
inherit_handles:
0
process_handle:
0x00000354
|
1
|
1 |
0
|
NtGetContextThread
|
thread_handle:
0x00000344
|
1
|
0 |
0
|
NtUnmapViewOfSection
|
base_address:
0x00400000
region_size:
4096
process_identifier:
2632
process_handle:
0x00000354
|
1
|
0 |
0
|
NtMapViewOfSection
|
section_handle:
0x00000364
process_identifier:
2632
commit_size:
0
win32_protect:
64
(PAGE_EXECUTE_READWRITE)
buffer:
base_address:
0x00400000
allocation_type:
0
()
section_offset:
0
view_size:
147456
process_handle:
0x00000354
|
1
|
0 |
0
|
NtSetContextThread
|
registers.eip:
2005598660
registers.esp:
1638384
registers.edi:
0
registers.eax:
4334086
registers.ebp:
0
registers.edx:
0
registers.ebx:
2130567168
registers.esi:
0
registers.ecx:
0
thread_handle:
0x00000344
process_identifier:
2632
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000344
suspend_count:
1
process_identifier:
2632
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000108
suspend_count:
1
process_identifier:
2216
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x000000fc
suspend_count:
1
process_identifier:
2280
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000108
suspend_count:
1
process_identifier:
2504
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x000000fc
suspend_count:
1
process_identifier:
2564
|
1
|
0 |
0
|